Cheap Hardware Parallelism Implies Cheap Security

Cheap Hardware Parallelism Implies Cheap Security
复制标题

DOI:
10.1109/fdtc.2007.4318988
复制
发表时间:
2007-09
期刊:
Workshop on Fault Diagnosis and Tolerance in Cryptography (FDTC 2007)
影响因子:
--
通讯作者:
O. Aciiçmez;Jean-Pierre Seifert
O. Aciiçmez;Jean-Pierre Seifert
中科院分区:
其他
文献类型:
--
作者:
O. Aciiçmez;Jean-Pierre Seifert

文献摘要

被引文献

相似文献

该论文提出了面向 PC 的旁道攻击领域的一个新方面。具体来说,我们提出了一种新颖的面向平方与乘法的侧通道攻击,该攻击对于某些同时多线程 CPU 架构来说非常独特,并且似乎在没有 SMT 硬件辅助的情况下无法在 CPU 架构上执行。我们的新颖攻击的独特性的一个简单原因是,它不像所有其他以前的 MicroArchitectural 侧通道攻击那样,依赖于上下文/进程切换之间具有持久状态属性的共享资源,例如缓存、BTB 等。相反,它基于以下事实:Intel 的超线程技术在其两个硬件线程之间共享 ALU 的大型并行整数(浮点)乘法器,值得注意的是,乘法器显然在上下文切换期间不保留其状态。随着最新的 OpenSSL 的变化,即针对旁路攻击的保护措施已经到位,参见(Brickell 等人,2006),我们的论文根本没有在 OpenSSL 库中引入新的漏洞。然而,我们的攻击具有以下不直观的特性。更长的密钥大小只会使我们的攻击场景变得更容易,而不是像人们乍一看所想象的那样更困难。因此,本文教导,特定多线程实现的唯一存在需要对底层硬件和软件之间的相互作用有非常深入的理解,以便适当地判断隐含的安全后果。
The paper presents a new aspect within that PC oriented side-channel attack arena. Specifically, we present a novel square vs. multiplication oriented side-channel attack which is very unique to certain simultaneous multi threading CPU architectures and it seems that it cannot be carried out on CPU architectures without SMT hardware assistance. The simple reason for this uniqueness of our novel attack is the fact that it doesn't rest - as all other previous MicroArchitectural side-channel attacks - upon a shared resource with the persistent state property between context/process switches, for e.g., caches, BTBs, etc. Instead, it is based upon the fact that Intel's hyper-threading technology shares the ALU's large parallel integer (floating-point) multiplier between its two hardware threads, where it is noteworthy that the multiplier obviously doesn't preserve its state during context switches. As the latest OpenSSL changes, i.e., protections against side-channels attacks are already in place, cf. (Brickell et al., 2006), our paper doesn't introduce a new vulnerability into the OpenSSL library at all. Nevertheless, our attack has the following unintuitive property. Longer key sizes just make our attack scenario easier and not more difficult as one could assume at first sight. Thus, the present paper teaches that the sole presence of particular multi threading implementations requires a very deep understanding of the interplay between the underlying hardware and software, in order to appropriately judge the implied security consequences.